From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3FB045867D8 for ; Fri, 11 Sep 2026 19:57:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156680; cv=none; b=UKAWbZFNutkbXeY9D/JDw1Ubue5ISe2BX8iwrerH5Mah7SHsNM7X9TFy72e7+TKpMwL6RUMB6M5rfI9doj840qjknrbSlfYvd9xgVGUoF9+/CpTae1PGlXSC60/b4VDg6i8SQMQYbb94d2rmOGCG27OdxhX1tiTPBRtS7mkbMRg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156680; c=relaxed/simple; bh=Mob8v7lxNFDq60TJGSEHXgqmO9Xq3iYSu6h9szOcJrw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Hceo2Gsi1hFAn92hv4ivVGBDSYcMpxG7R2NzylinYDwYATaWlmcYrGvYMDx3xoihaw95gcunxklvpYoVjGOQ43tCnHo/zsXSMDXWf6JV+7zxdqytRWzq6MfM3JEIJv8jYXpoTEqUGcJslpv7/aqw/fDtG5lrUEuYSU1tnDbQAE0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Uus/maY1; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Uus/maY1" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 450581F0089D; Fri, 11 Sep 2026 19:57:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156675; bh=rFja8tiCPA8BEuIjrJ5fDK9sX1DR0aIfTODcQPA6qUs=; h=From:To:Cc:Subject:Date:Reply-To; b=Uus/maY1RccZ8Nrry/MYX1j0d8wsGLFsxuTCaGp7Tu2rqPDKQglDTRj+hyQa39EwQ lLACJ1upamGxPfuNp598pw3WOs8/C4RSS+683AhMAor8/hXcT1eWNsyYgjYfQGweKs I6Cn7KWk9N/jYDxdp76XCmknq6saNWgqHGej/KkE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89597: fbdev: uvesafb: unregister connector callback on init failure Date: Fri, 11 Sep 2026 21:44:46 +0200 Message-ID: <2026091132-CVE-2026-89597-a7ca@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2727; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=wa3y+u1mwwN+ICWjvuFySR1JniOL2B0Wp+HqTL3zKrk=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLInPcO3WOqkn+YFt+2/X2qlW5p/o6yqZLNj5qnSvQc kh5AZtvRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAExkcyrD/Oj9v2tFmgovFpmd OvWzJmn725tddxnmGfy1Mfv0VkjI2mtHvJYt47lT1QWvAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: fbdev: uvesafb: unregister connector callback on init failure uvesafb_init() registers the v86d connector callback before registering the platform driver. If platform_driver_register() fails, the function returns the error directly and leaves the connector callback registered. The later platform-device failure path already unregisters the callback. Add the same cleanup before the final return when platform-driver registration fails. This issue was identified during our ongoing static-analysis research while reviewing kernel code. The Linux kernel CVE team has assigned CVE-2026-89597 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.24 with commit 8bdb3a2d7df48b861972c4bfb58490853a228f51 and fixed in 6.12.109 with commit 9f8a822b44c42502f105cf6574f4867067eecdd0 Issue introduced in 2.6.24 with commit 8bdb3a2d7df48b861972c4bfb58490853a228f51 and fixed in 6.18.50 with commit 466a8af0dee2cf745307155e26884e19a37b7e15 Issue introduced in 2.6.24 with commit 8bdb3a2d7df48b861972c4bfb58490853a228f51 and fixed in 7.2.4 with commit 9e768ae51426af2034d479133cfd73010d641b1a Issue introduced in 2.6.24 with commit 8bdb3a2d7df48b861972c4bfb58490853a228f51 and fixed in 7.3-rc1 with commit de8db23aa7c337e606fca9faf48b3ba72968597a Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89597 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/video/fbdev/uvesafb.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/9f8a822b44c42502f105cf6574f4867067eecdd0 https://git.kernel.org/stable/c/466a8af0dee2cf745307155e26884e19a37b7e15 https://git.kernel.org/stable/c/9e768ae51426af2034d479133cfd73010d641b1a https://git.kernel.org/stable/c/de8db23aa7c337e606fca9faf48b3ba72968597a